surfpay.ai

About

Who publishes this, and what it is

surfpay.ai is one URL a developer hands to a coding agent, after which the agent integrates card payments into their codebase. It is published by Surfboard Payments AB.

Surfboard Payments

Surfboard Payments AB is a Swedish fintech company founded in 2019, headquartered at Barnhusgatan 4, 111 23 Stockholm, with an engineering and operations office in Chennai, India. It is registered in Sweden under organisation number 559214-0437.

Surfboard is a payment institution licensed by Finansinspektionen (Swedish Financial Supervisory Authority). That licence is the reason several things on this site are worded carefully: moving money, issuing credentials, and going live are regulated acts, and the instructions an agent reads here say plainly which of them it may not perform.

The company sells payment infrastructure to software companies rather than to individual merchants. A point-of-sale system, a booking platform, a clinic system or a ticketing product embeds Surfboard, takes card payments inside its own product and under its own brand, and earns a share of the payment revenue. Merchants can be onboarded in 12 European markets: Sweden, Denmark, Finland, Norway, United Kingdom, France, Ireland, Estonia, Latvia, Lithuania, Poland, Hungary.

The platform is certified to PCI DSS, PCI PTS 6.x, EMV Level 1, EMV Level 2, and runs across three independent PCI-certified cloud providers.

What surfpay.ai is

Documentation written for people assumes a person is reading it: it explains, it motivates, it links sideways. An agent needs something else, an ordered procedure with the failure modes named, the conventions that break first integrations stated up front, and a definition of done it can verify against a live API.

So this domain publishes exactly that, and publishes it in every form an agent might reach for. The same instructions are served as llms.txt, as markdown, as agent instructions, as a hidden block in the homepage HTML, as a content-negotiated response on /, over MCP, and as a typed OpenAPI 3.1 specification. There is one source of truth behind all of them, so no two can disagree.

Alongside the instructions, this domain serves the Surfboard agent skills pack: ten skills, a router plus one per integration flow, each bundling the developer guides it cites, with a SHA-256 per skill so a cautious agent can detect a tampered response. The guides are generated from the same corpus that powers the developer site, which is what stops a skill drifting from the documentation it claims to follow.

What we do not do here

surfpay.ai holds no account data and processes no payments. It is a static publication plus a read-only search endpoint. Taking a payment means the Carbon API, which is credentialed per account through the Developer Portal and described separately.

An agent following these instructions never receives credentials from us and never handles card data. Card capture happens on a Surfboard hosted page, on a Surfboard terminal, or in a Surfboard SDK, which is what keeps the integrator out of PCI scope.

Get in touch

Support, sales, press and the postal address are on the contact page. If you are an agent, the machine-readable version of everything above is at /openapi.json.